LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 8, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 11, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-1340 to its Known Exploited Vulnerabilities catalog on Apr 8, 2026, with a federal patch deadline of Apr 11, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. The flaw affects systems that manage mobile endpoints and therefore gives an attacker a direct path into an organization's device-management infrastructure.

How it works

CWE-94 describes improper control of code generation, allowing an attacker to supply input that the application later executes as code. In this case the weakness permits unauthenticated remote code execution, so an attacker can submit crafted input over the network and have it run on the server without prior authentication.

Am I affected? How to find it in your systems

Inventory all deployments of Ivanti Endpoint Manager Mobile (EPMM). The product typically runs as a server component that communicates with mobile devices and management consoles. Check both on-premises installations and any cloud-hosted instances. Confirm the exact versions and configurations in use against the vendor advisory, as only the advisory lists the affected releases.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, review and apply any additional hardening steps the vendor provides for this class of code-injection issue.

If you can't patch immediately

Follow the mitigations listed in the vendor instructions. Where EPMM is delivered as a cloud service, apply the controls required by CISA BOD 22-01. If mitigations cannot be implemented, discontinue use of the affected product until a fix is in place. Network segmentation that restricts unauthenticated access to the EPMM server can reduce exposure while remediation is pending.

If your data may have been exposed

Code-injection vulnerabilities that permit remote code execution have been used to obtain persistent access in other environments. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Mobile (EPMM)
WeaknessCWE-94
Added to CISA KEVApr 8, 2026
Federal patch deadlineApr 11, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities